multiple
multiple 相关平台内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
IBM Lotus Domino iCalendar – Email Address Stack Buffer Overflow
source: http://labs.mwrinfosecurity.com/advisories/lotus_domino_ical_stack_buffer_overflow/
CS-Cart 1.3.3 – ‘install.php’ Cross-Site Scripting
# Exploit Title: [CS CART 1.3.3 INSTALL.PHP XSS]
Accton-based switches (3com / Dell / SMC / Foundry / EdgeCore) – Backdoor Password
On the 15th of august 2009, at the HAR2009 conference, the existence of a backdoor password in Accton-based switches ...
Adobe Acrobat and Reader 9.3.4 – ‘AcroForm.api’ Memory Corruption
source: https://www.securityfocus.com/bid/42701/info
Adobe Acrobat Reader < 9.x - Memory Corruption
---------------------------------------------------------------------------
Nagios XI – ‘users.php’ SQL Injection
source: https://www.securityfocus.com/bid/42661/info
Flock Browser 3.0.0 – Malformed Bookmark HTML Injection
source: https://www.securityfocus.com/bid/42556/info
Adobe ColdFusion – Directory Traversal
# Working GET request courtesy of carnal0wnage:
ServletExec – Directory Traversal / Authentication Bypass
source: https://www.securityfocus.com/bid/42411/info
Kleeja Upload – Cross-Site Request Forgery (Change Admin Password)
# Exploit Title: Kleeja Upload - CSRF Change Admin Password
Zendesk – Multiple Vulnerabilities
/¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯\
Play! Framework 1.0.3.1 – Directory Traversal
Exploit Title: Play! Framework
Oracle MySQL < 5.1.50 - Privilege Escalation
source: https://www.securityfocus.com/bid/43677/info
Oracle MySQL – ‘ALTER DATABASE’ Remote Denial of Service
A vulnerability was reported in MySQL. A remote authenticated user can cause denial of service conditions.
IBM Java – UTF8 Byte Sequences Security Bypass
source: https://www.securityfocus.com/bid/41918/info
Monolith Lithtech Game Engine – Memory Corruption
source: https://www.securityfocus.com/bid/41851/info
libpng 1.4.2 – Denial of Service
Exploit Title: libpng > 1) ^ poly;
Novell Groupwise Internet Agent – Stack Overflow
#####################################################################################
Unreal Engine – ‘ReceivedRawBunch()’ Denial of Service
source: https://www.securityfocus.com/bid/41737/info
Novell Groupwise Webaccess – Stack Overflow
#####################################################################################
Struts2/XWork < 2.2.0 - Remote Command Execution
Friday, July 9, 2010
Oracle WebLogic Server 10.3.3 – Encoded URL
source: https://www.securityfocus.com/bid/41620/info
Oracle Business Process Management 10.3.2 – Cross-Site Scripting
source: https://www.securityfocus.com/bid/41617/info
Asterisk Recording Interface 0.7.15/0.10 – Multiple Vulnerabilities
source: https://www.securityfocus.com/bid/41571/info
dotDefender – Cross-Site Scripting Security Bypass
source: https://www.securityfocus.com/bid/41560/info
Ubisoft Ghost Recon Advanced Warfighter – Integer Overflow / Array Indexing Overflow
source: https://www.securityfocus.com/bid/41459/info
Unreal Engine 2.5 – ‘UpdateConnectingMessage()’ Remote Stack Buffer Overflow (PoC)
source: https://www.securityfocus.com/bid/41424/info
id Software id Tech 4 Engine – ‘key’ Packet Remote Code Execution
source: https://www.securityfocus.com/bid/41460/info
EDItran Communications Platform (editcp) 4.1 – Remote Buffer Overflow
source: https://www.securityfocus.com/bid/41342/info
ISC DHCPD – Denial of Service
#!/usr/bin/env python
Xplico 0.5.7 – ‘add.ctp’ Cross-Site Scripting (2)
source: https://www.securityfocus.com/bid/41322/info
Kryn.cms 6.0 – Cross-Site Request Forgery / HTML Injection
source: https://www.securityfocus.com/bid/41229/info
LIOOSYS CMS – ‘news.php’ SQL Injection
##############################################################################
CubeCart PHP 4.3.x – ‘shipkey’ SQL Injection
SQL Injection in CubeCart PHP Free & Commercial Shopping Cart Application
Ecomat CMS – SQL Injection
Vulnerability ID: HTB22390